4.3

CVE-2008-7175

NextGEN Gallery Plugin <= 1.9.0 - Authenticated (Admin+) Stored Cross-Site Scripting

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in NextGEN Gallery 0.96 and earlier plugin for Wordpress allows remote attackers to inject arbitrary web script or HTML via the picture description field in a page edit action.
Mögliche Gegenmaßnahme
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery: Update to version 1.9.1, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Alex Rabe ≫ Nextgen Gallery Version <= 0.96
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.33
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.34
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.35
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.36
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.37
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.39
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.40
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.41
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.42
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.43
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.50
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.51
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.52
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.60
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.61
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.62
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.63
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.64
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.70
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.71
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.72
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.73
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.74
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.80
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.81
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.82
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.83
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.90
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.91
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.92
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.93
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.94
   Wordpress ≫ Wordpress
Alex Rabe ≫ Nextgen Gallery Version 0.95
   Wordpress ≫ Wordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
Version *-1.9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.47% 0.703
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://osvdb.org/51428
http://www.securityfocus.com/archive/1/493182/100/0/threaded
https://www.wordfence.com/threat-intel/vulnerabilities/id/f7ff27af-2b78-4214-9232-042357287ba8
Third Party Advisory